!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

707 Members
Coordination and triage of security issues in nixpkgs218 Servers

Load older messages


SenderMessageTime
31 Jan 2024
@bytebandit:tac.lolDerivationDingus joined the room.09:35:10
@yuka:yuka.dev@yuka:yuka.dev joined the room.13:19:37
@delroth:delroth.netdelrothhttps://curl.se/docs/CVE-2024-0853.html (low sev)13:37:20
@hexa:lossy.networkhexataking that14:08:31
@shlevy:matrix.orgshlevy joined the room.14:55:05
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/28529515:19:05
1 Feb 2024
@deightz:matrix.orgdeightz joined the room.04:05:10
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its)https://snyk.io/blog/leaky-vessels-docker-runc-container-breakout-vulnerabilities/ TL;DR multiple container escapes in docker. runc, buildkit and containerd need to be updated. I'm on it07:50:44
@sophie:catgirl.cloud⛧-440729 [sophie raven] (it/its)Well, was already done by the bot, though the first two of these aren't merged yet https://github.com/NixOS/nixpkgs/pull/285438 https://github.com/NixOS/nixpkgs/pull/285407 https://github.com/NixOS/nixpkgs/pull/28541807:54:17
@leona:leona.isleonaI created some backport PRs to 23.11 (automatic wouldn't have worked): https://github.com/NixOS/nixpkgs/pull/285507 https://github.com/NixOS/nixpkgs/pull/285508 https://github.com/NixOS/nixpkgs/pull/28551009:34:13
@ximnoise:infosec.exchangeximnoise joined the room.09:53:02
@ximnoise:infosec.exchangeximnoise set a profile picture.10:03:31
@delroth:delroth.netdelrothhttps://mastodon.social/@MastodonEngineering/111856895554844910 the patches are out apparently15:22:11
@delroth:delroth.netdelrothhttps://github.com/mastodon/mastodon/releases/tag/v4.2.5 presumably15:22:28
@delroth:delroth.netdelrothand taken care of by https://github.com/NixOS/nixpkgs/pull/28555815:22:45
@schmittlauch:ohai.isschmittlauch (he/him) joined the room.16:55:14
@kudzu:envs.net@kudzu:envs.net left the room.17:45:38
2 Feb 2024
@shivayspec:matrix.orgSpecx joined the room.07:11:03
@daniel:routing.rocksdan_nrw joined the room.09:52:50
3 Feb 2024
@neonmei:matrix.orgneonmei changed their profile picture.04:01:08
@raboof:matrix.orgraboof changed their display name from raboof to raboof @FOSDEM.07:38:53
@networkexception:chat.upi.li@networkexception:chat.upi.li changed their profile picture.11:53:46
@hexa:lossy.networkhexahttps://anydesk.com/en/public-statement14:25:06
@hexa:lossy.networkhexalatest version uses a new codesigning cert14:25:57
@hexa:lossy.networkhexaimage.png
Download image.png
14:27:03
@hexa:lossy.networkhexaI don't think they sign linux tarballs 🙂 14:27:11
@tgerbet:matrix.orgtgerbetNope they do not, at least not for what's used in nixpkgs package14:28:18
@tgerbet:matrix.orgtgerbetBut the package pin did not change in the last 5 months so we are probably fine (unless they were already compromised)14:30:31
@k900:0upti.meK900My kingdom for remote desktop software that doesn't suck 14:33:54
@hexa:lossy.networkhexawayland support when14:34:08

Show newer messages


Back to Room ListRoom Version: 6